CVE-2023-34923

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/06/2023
Last modified:
30/06/2023

Description

XML Signature Wrapping (XSW) in SAML-based Single Sign-on feature in TOPdesk v12.10.12 allows bad actors with credentials to authenticate with the Identity Provider (IP) to impersonate any TOPdesk user via SAML Response manipulation.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:topdesk:topdesk:12.10.12:*:*:*:*:*:*:*